๐Ÿ” CVE Alert

CVE-2026-48997

HIGH 7.1

e107: Command Injection via shell expansion in ImageMagick resize destination path

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ImageMagick resize destination path. In resize_image(), the source path is escaped with escapeshellarg(), but the destination path is inserted inside raw double quotes in the convert command; in the submit-news upload flow, that destination filename includes the first six characters of user-controlled news title input. Because the title filter removes literal spaces but not tab characters, and shell expansions such as $(...) and backticks can survive into the quoted destination argument, /bin/sh -c may evaluate attacker-controlled input. Exploitation is possible only when all of the following non-default settings are enabled: resize_method=ImageMagick, subnews_attach=1, upload_enabled=1, subnews_resize is numeric between 30 and 5000, and the attacker is a non-admin in classes permitted by both subnews_class and upload_class. This issue has been fixed in version 2.3.6.

CWE CWE-78
Vendor e107inc
Product e107
Published Jun 17, 2026
Stay Ahead of the Next One

Get instant alerts for e107inc e107

Be the first to know when new high vulnerabilities affecting e107inc e107 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
High

Affected Versions

e107inc / e107
< 2.3.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/e107inc/e107/security/advisories/GHSA-3j33-c9v4-4p42 github.com: https://github.com/e107inc/e107/releases/tag/v2.3.6